Input validation error in envoy - CVE-2023-27488

 

Input validation error in envoy - CVE-2023-27488

Published: April 5, 2023 / Updated: April 6, 2023


Vulnerability identifier: #VU74474
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-27488
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to escalate privileges on the system.

The vulnerability exists due to insufficient validation of user-supplied input when "failure_mode_allow: true" is configured for ext_authz filter. A remote attacker can pass specially crafted input to the application and gain elevated privileges on the target system.


Affected software

envoy
Amazon Linux AMI
Istio
OpenShift Service Mesh
IBM Watson Assistant for IBM Cloud Pak for Data

How to mitigate CVE-2023-27488

Install updates from vendor's website.

envoy - addressed in versions 1.22.10, 1.23.7, 1.24.5, 1.25.4
Istio - addressed in versions 1.15.7, 1.16.4, 1.17.2
OpenShift Service Mesh - update to 2.2.9
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.7.0

External References

Related Security Bulletins